Description
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive log files. Attackers can directly browse the /log directory to retrieve system and sensitive information without authentication.
Problem types
Exposure of Information Through Directory Listing
Product status
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5732.php (Zero Science Lab Disclosure (ZSL-2022-5732))
packetstormsecurity.com/...o-2.x-Information-Disclosure.html (Packet Storm Security Exploit Details)
exchange.xforce.ibmcloud.com/vulnerabilities/247921 (IBM X-Force Vulnerability Exchange Entry)
www.sound4.com/ (SOUND4 Product Homepage)
www.vulncheck.com/...nformation-disclosure-via-log-directory (VulnCheck Advisory: SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Information Disclosure via Log Directory)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.